Governance for Power BI That Leaves Your Organization

Structure before delivery, governance before exposure — governance is not a review meeting, it is infrastructure. Reporting Hub decides who each external viewer is, what they are allowed to open, and what AI is allowed to tell them.

The problem

Internal governance assumes everyone is inside

Power BI’s governance model is built for people in your own tenant. An external audience breaks nearly every assumption it makes.

Inside your organisation, governance can lean on things that are simply true. Every viewer has an account you issued, a licence you pay for and a place in your directory. If somebody opens a report they should not have, they are an employee, and the fix is a conversation.

None of that holds once the audience is customers, partners and regulators. They are not in your directory. They must not be able to discover one another. And when something does go wrong, the people asking what happened do not work for you — they work for the customer.

  Internal BI External delivery
Who the viewer is An employee already in your directory A customer who has never had an account with you
How they are licensed A Power BI seat you buy for them No Power BI seat at all
What decides access Membership of a workspace or app The tenant they belong to, and what an admin assigned to it
Keeping audiences apart Rarely the point The first requirement, and the one with no margin
Cost of showing the wrong row An internal conversation A disclosure to somebody else’s customer
Who asks for the evidence Your own audit team Your customer’s auditors, and their regulator
Governance

One orchestration layer, every output governed

Configuration, access and audit are enforced by the platform itself — not by a review meeting that has to happen every time something ships.

Configuration Before Exposure

Every BI Genius agent is configured and enabled by an admin before an external audience can reach it — scope, sources and audience all settled up front.

Per-Tenant Assignment

A report reaches an audience only once an admin has assigned it to that tenant, and every tenant reads the same governed semantic model — so no one ends up with 200 versions of the truth.

Role-Based Access + RLS

Reporting Hub access control works with your existing Power BI row-level security to scope every report, page, and row to the right viewer.

Audit Logging

A system of record for external intelligence — what was delivered, to whom, when. Compliance-grade AI audit trails on Enterprise+.

Knowledge Boundaries

Each BI Genius agent is scoped to the semantic models and data sources you assign — configured per tenant, per customer.

Admin Oversight Dashboard

See what AI is being asked and how it answers across every tenant, in one place — transparency for your team before your customers.

How it works

Decided before exposure, not after

Governance that depends on somebody remembering to check is not governance. The boundaries are settled first, then enforced on every delivery.

There are two ways to control what an external audience receives. You can inspect each thing on its way out, or you can decide the boundaries once and have the platform hold them. Only the second survives contact with a real customer base — the first turns every report change and every question into a queue.

Reporting Hub takes the second. An admin decides what a tenant is, which reports it can open and what its BI Genius agent may reach, before that tenant has access to anything at all. From then on every delivery happens inside those boundaries, and every one of them is recorded.

Configuring a tenant

Done once, before that customer can reach anything at all.

  1. Configure the tenant. Its identity provider, its branding, its users, and the reports it is allowed to open.
  2. Scope the agent. Which semantic models and sources BI Genius may reach for this tenant, and what it is allowed to address.
  3. Enable it. Nothing is reachable until an admin turns it on, so exposure is a deliberate act rather than a side effect of publishing.
  4. Deliver inside the boundaries. Every report and every AI answer is produced within what was configured, with row-level security applied per viewer.
  5. Oversee it. The Admin Oversight Dashboard shows what is being asked and how it is answered; the audit trail records what was delivered, to whom, and when.
Governed AI

What an admin sets, and what the customer gets

BI Genius is governed per tenant at configuration time. This is what that actually consists of.

  What an admin configures What the customer experiences
Knowledge boundaries The semantic models and data sources this tenant’s agent may reach Answers drawn only from the data assigned to them
Agent scope What the agent serves and what it is allowed to address An assistant aimed at their reporting, not a general chatbot
Identity Which provider the tenant signs in with Their own sign-in — Entra ID, Okta, Auth0 or any OpenID Connect provider
Row-level security Your existing Power BI RLS, mapped to external identities Only their own rows, by the rules you already wrote
Report assignment Which reports this tenant can open A report appears for them once it has been assigned
Explainability On, so every answer carries its working Source attribution, the decision path and the underlying DAX

Explainability output is aimed at your admins — it is what lets your team stand behind an answer when a customer questions it.

Evidence

Proving it afterwards

Governance you cannot evidence is an assertion. The audit trail is what turns it into a record.

The question that ends most external analytics procurements is not whether you have controls. It is whether you can show, months later, what a particular customer’s users were shown and what your AI told them. That is a different artefact from an internal activity log, because the person asking for it does not work for you.

Reporting Hub records delivery per tenant: what was opened, by whom, and when — and for BI Genius, what was asked and what came back. Full audit logging is included from the Growth tier, and Enterprise+ adds compliance-grade AI audit trails for regulated environments.

Because the whole platform runs inside your own Azure subscription, that record is yours and stays in your tenant. See how the deployment is structured.

Questions

Governance FAQs

What happens before an AI answer reaches a customer?

An admin configures the agent before it is exposed: which semantic models it can reach, which audience it serves, and what it is allowed to address. It reaches customers only once that is set and an admin enables it. From there every answer is produced inside those boundaries, with source attribution and the underlying DAX available to your admins, and every question and answer recorded in the audit trail.

How do external users sign in?

Through your branded platform or your own application, using Microsoft Entra ID, Okta, Auth0 or any OpenID Connect provider. Customers never see a Power BI sign-in and never need a Power BI account. Your directory, your MFA and your conditional access policies all still apply.

Can two customers ever see each other’s data?

No. Each tenant is a separate construct in the platform, with its own users, its own assigned reports and its own agent configuration. On top of that your existing Power BI row-level security is applied per authenticated viewer, so isolation is enforced twice — once by the tenancy model and once by the model itself.

How does row-level security carry into external delivery?

Your existing Power BI RLS rules keep working — Reporting Hub maps external identities into them, so the same row-level scoping that protects internal viewers protects external ones. You do not rewrite security rules for the outside world.

What is recorded in the audit trail?

What was delivered, to whom, and when — for reports and AI alike, including the questions asked of BI Genius and the answers returned, per tenant. It is the record you hand to a customer’s auditor when they ask what their users were shown.

Which tiers include audit logging?

Full audit logging is included from the Growth tier; Enterprise+ adds compliance-grade AI audit trails suitable for regulated environments. Compare plans.

Can different customers get different AI capabilities?

Yes. BI Genius agents are configured per tenant, so what an agent can reach and what it may address is set separately for each customer before that customer can use it. That is also what makes a premium AI tier possible: you can sell it to some tenants and not others.

Who can change governance settings?

Platform admins on your side, inside your own deployment. Reporting Hub runs in your Azure subscription, so the people who configure tenancy, access and agent scope are your staff — not ours, and not a third party’s.

Does our data leave our Azure environment?

No. Reporting Hub and BI Genius both run inside your own Azure tenant. Prompts and data are not sent to an external service, there is no third-party hosting layer, and there is no data egress — AI inference included. Security and trust.

Does any of this require Microsoft Fabric?

No — but you do need a capacity. Reporting Hub runs on either a Power BI Embedded capacity (A or EM SKU) or a Fabric capacity (F SKU), deployed into your own Azure subscription and billed there by Microsoft. Governance itself runs against the semantic models you already have. See where Fabric and Copilot fit.
Talk to Our Team